Cisco has warned that three distinct threat clusters linked to ransomware and state-sponsored cyberattacks are actively exploiting two recently patched vulnerabilities in Cisco Secure Firewall Management Center (FMC).
The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, can provide attackers with unauthorized access to vulnerable FMC systems and, in some cases, allow them to obtain sensitive information, execute commands, and establish persistent access to enterprise networks.
Cisco Talos researchers said they identified three separate clusters of post-compromise activity targeting Secure FMC deployments.
Critical Cisco FMC Vulnerability Exploited in the Wild
The most serious vulnerability is CVE-2026-20079, which carries a maximum CVSS score of 10.0.
The flaw is an authentication-bypass vulnerability affecting the web interface of Cisco Secure FMC.
An unauthenticated remote attacker could exploit the vulnerability to bypass authentication and execute script files on a vulnerable appliance. Successful exploitation can ultimately provide root-level access to the underlying operating system.
The second vulnerability, CVE-2026-20316, has a CVSS score of 5.3.
This flaw could allow an unauthenticated remote attacker to log in using a low-privileged account and access sensitive information stored on affected systems. Cisco said the vulnerability can also be combined with other Secure FMC flaws to escalate privileges.
Three Threat Clusters Target Vulnerable FMC Systems
Cisco Talos identified three distinct clusters exploiting the vulnerabilities.
UAT-12197 Deploys Web Shells and Command Executors
The first cluster, tracked as UAT-12197, has exploited CVE-2026-20079 to gain access to vulnerable FMC appliances.
After compromising a system, the attackers deployed JSP-based web shells and a Java Archive (JAR)-based command executor.
These tools allowed the threat actors to interact with internal databases and collect authentication-related information and credentials.
The activity demonstrates how an initial vulnerability in a security-management appliance can be leveraged to gain access to sensitive internal information.
UAT-11823 Deploys Reverse Shells and Cyclops Blink
The second cluster, UAT-11823, has exploited both CVE-2026-20079 and CVE-2026-20316.
Talos observed the attackers deploying a Netcat-based reverse shell, along with Bash scripts designed to harvest configuration information from managed network devices.
The group also deployed a variant of Cyclops Blink, a modular Linux-based malware previously associated with the Russian state-sponsored hacking group Sandworm.
The use of Cyclops Blink is particularly significant because it suggests that compromised Secure FMC appliances may be used as a foothold for broader network intrusion activity.
UAT-11988 Uses FMC Tools to Deploy Qilin Ransomware
The third cluster, UAT-11988, is associated with ransomware activity.
Unlike the other clusters, the attackers primarily exploited CVE-2026-20316 for initial access.
Once inside the environment, the threat actors used legitimate functionality already available within Secure FMC as part of a living-off-the-land (LotL) strategy.
This approach allows attackers to conduct malicious operations using trusted tools and capabilities already present on the compromised system, potentially making detection more difficult.
Cisco said the attackers used the compromised environment to:
- Conduct extensive reconnaissance
- Deploy tunneling tools for continued network access
- Collect credentials
- Identify potential endpoints for encryption
- Disable or terminate security tools
- Prepare targeted systems for ransomware deployment
- Deploy Qilin ransomware
The activity highlights how vulnerabilities in network security infrastructure can ultimately lead to ransomware deployment across an organization’s wider environment.
Attackers Turn Security Infrastructure Into an Entry Point
Cisco’s findings demonstrate the risks associated with compromising security-management appliances.
Secure Firewall Management Center systems often have privileged visibility into enterprise networks and can contain sensitive configuration information related to managed devices.
Once attackers gain access, they may be able to use that information to map an organization’s infrastructure, harvest credentials, identify valuable targets, and move deeper into the network.
The presence of multiple independent threat clusters exploiting the same vulnerabilities also increases the urgency for organizations operating affected FMC versions.
Cisco Urges Customers to Apply Hotfixes
Cisco has urged customers to immediately install the security updates released for CVE-2026-20079 and CVE-2026-20316.
“Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco.”
The company also said it plans to release a broader hardening update addressing several internally discovered vulnerabilities.
Organizations should prioritize vulnerable Secure FMC deployments, particularly systems that are directly accessible from untrusted networks or have not yet received Cisco’s security updates.
CVE-2026-20079 Added to CISA’s KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog.
Federal Civilian Executive Branch (FCEB) agencies were required to apply the relevant security updates by September 12, 2026.
The second vulnerability, CVE-2026-20316, was added to the KEV catalog in late July 2026.
The inclusion of both vulnerabilities in CISA’s KEV catalog confirms that they are being actively exploited and should be treated as a high-priority patching issue.
What Organizations Should Do
Organizations using Cisco Secure Firewall Management Center should:
- Apply Cisco’s hotfixes immediately for CVE-2026-20079 and CVE-2026-20316.
- Review FMC systems for signs of unauthorized access or web-shell activity.
- Investigate unexpected reverse shells, tunneling tools, and command execution.
- Check managed-device configurations for unauthorized changes.
- Review authentication logs and newly created or modified accounts.
- Monitor for signs of Cyclops Blink or Qilin ransomware activity.
- Investigate unusual outbound connections from FMC appliances.
Because Cisco has confirmed active exploitation, organizations should not treat these vulnerabilities as routine patching items.
Cisco FMC Customers Face Active Exploitation Risk
The exploitation of these two Secure FMC vulnerabilities by multiple threat clusters underscores the importance of securing network-management infrastructure.
The observed attacks range from credential theft and reconnaissance to state-linked malware deployment and full-scale ransomware operations.
With CVE-2026-20079 and CVE-2026-20316 now present in CISA’s Known Exploited Vulnerabilities catalog, organizations should prioritize remediation and conduct retrospective threat hunting to determine whether their appliances were compromised before patches were applied.
Cisco customers should apply the available hotfixes as soon as possible and investigate potentially affected systems for signs of post-compromise activity.
